Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Detection Engineering Lab

A full-cycle detection engineering project demonstrating the complete SOC workflow: log ingestion, Sigma rule development, alert triage, MITRE ATT&CK mapping, rule tuning, and incident response documentation.


Architecture

detection-engineering-lab/
├── detections/          # Sigma rules (8 rules, 12 ATT&CK techniques)
├── investigations/      # Documented alert triage investigations (5 cases)
├── playbooks/          # Incident response playbook + workflow
├── dashboards/         # Kibana dashboard exports (JSON)
├── logs/               # Sample log sources and field mappings
└── README.md

Stack: Elasticsearch, Kibana, Logstash, Winlogbeat, Elastic Agent
Log sources: Windows Event Logs (Security, System, Sysmon, PowerShell), firewall logs
Detection format: Sigma (compatible with Splunk, Sentinel, QRadar, Elastic Security)


Detection Coverage

# Rule ATT&CK Technique Severity Tuned
1 Suspicious PowerShell Encoded Command T1059.001 High Yes
2 Kerberoasting Activity Detected T1558.003 High Yes
3 LSASS Memory Dump via Task Manager T1003.001 Critical Yes
4 Remote Desktop Protocol (RDP) from Public IP T1021.001 Medium Yes
5 Scheduled Task Creation for Persistence T1053.005 High Yes
6 WMI Process Execution for Lateral Movement T1047 High Yes
7 Credential Dumping via ProcDump or Mimikatz T1003.001 Critical Yes
8 Exfiltration Over DNS (Tunneling Detection) T1048.003 Medium Yes
9 Service Execution for Privilege Escalation T1543.003 High Yes
10 Account Discovery via net.exe Commands T1087.001 Low Tuned (reduced FP)

Investigations

Each investigation follows a structured triage format: alert trigger, initial analysis, evidence collection, MITRE ATT&CK mapping, timeline reconstruction, conclusion, and lessons learned.

# Case ATT&CK Techniques Verdict
1 PowerShell Download Cradle Detected T1059.001, T1105 True Positive
2 Unusual RDP Connection After Hours T1021.001, T1078 True Positive
3 Scheduled Task Named "WindowsUpdate" T1053.005, T1059.001 False Positive (IT automation)
4 Kerberoasting Followed by Lateral Movement T1558.003, T1021.002, T1003.001 True Positive (Full IR)
5 DNS Tunneling to Rare External Domain T1048.003, T1071.004 True Positive (C2 beacon)

Incident Response: Kerberoasting to Domain Compromise

Investigation #4 is a full incident response report covering the complete attack chain:

  • Initial access: Valid domain credentials obtained via phishing
  • Discovery: BloodHound collection via Sharphound (T1087.002)
  • Credential access: Kerberoasting attack targeting service accounts (T1558.003)
  • Lateral movement: PsExec to domain controller (T1021.002)
  • Credential dumping: LSASS dump via procdump on DC (T1003.001)
  • Containment: Account disable, session termination, network isolation
  • Remediation: KRBTGT password reset (twice), service account rotation, GPO audit
  • Detection improvements: New Sigma rules deployed, alert thresholds tuned, EDR block rules added

Full incident report →


Rule Tuning Examples

The investigations/ directory documents false positive analysis and rule refinement:

  • Account Discovery (net.exe): Reduced 94 alerts/day to 3 alerts/day by filtering IT admin workstations and service accounts
  • Scheduled Task Creation: Whitelisted known IT automation tasks by TaskName and Author pattern
  • RDP from Public IP: Added geolocation context — only alert on non-UK countries and first-seen IPs

Detection Engineering Workflow

Log Source → Logstash/Agent → Elasticsearch → Kibana Rule → Alert → Investigation → MITRE ATT&CK Mapping → Rule Tuning → Documentation

Setup

This lab was built on a local ELK stack with the following components:

# Elastic Stack
docker-compose up -d elasticsearch kibana logstash

# Windows event collection
winlogbeat setup --dashboards
winlogbeat -e

# Deploy Sigma rules to Elastic
sigma convert -t elastalert -p ecs_windows detections/*.yml > elastic_rules.ndjson

Author

Gideon Opukeme — Cybersecurity Engineer
MSc Cyber Security, University of Aberdeen
github.com/Gideon145

About

Full-cycle detection engineering lab: Sigma rules, ATT&CK-mapped investigations, incident response workflow, and rule tuning. Built on the Elastic Stack with real Windows event logs.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors